CVE-2021-38191

NameCVE-2021-38191
DescriptionAn issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the wrong thread.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rust-tokio (PTS)bullseye0.1.14-2fixed
bookworm1.24.2-1fixed
sid, trixie1.35.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rust-tokiosource(unstable)(not affected)

Notes

- rust-tokio <not-affected> (Introduced in 0.3.0)
https://rustsec.org/advisories/RUSTSEC-2021-0072.html
https://github.com/tokio-rs/tokio/issues/3929
https://github.com/tokio-rs/tokio/pull/3934
https://github.com/tokio-rs/tokio/pull/3934/commits/84394949228d11d1f68925e26f36c435946b9d11

Search for package or bug name: Reporting problems